Unauthenticated Shell via MAVLink Enables Remote Command Execution
PX4 Autopilot — flight control software for drones and unmanned vehicles — accepts unauthenticated SERIAL_CONTROL MAVLink messages that can spawn an interactive shell. The flaw appears in Autopilot v1.16.0_SITL_latest_stable and is tracked as CVE-2026-1579. MAVLink does not require cryptographic authentication by default, so deployments with MAVLink 2.0 message signing disabled will accept unsigned SERIAL_CONTROL messages. Affected sectors include transportation, defense, and other critical infrastructure where MAVLink interfaces are reachable.